All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.18.0"
},
{
"introduced": "0"
},
{
"fixed": "2.18.0"
}
]
}